Skip to main content

CVE-2026-107303: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jhipster generator-jhipster

0
High
Published: 10/08/2026 (10/08/2026, 17:40:29 UTC)
Source: CVE Database V5
Vendor/Project: jhipster
Product: generator-jhipster

Description

## Summary Applications generated by generator-jhipster v9.2.0 can persist user-controlled Blob ContentType values and later use those values as the MIME type for client-side Blob objects. The shared generated `openFile` helper creates an object URL from the Blob and opens it in a new window. For Blob-bearing entities writable by normal authenticated users, this creates a stored XSS chain: attacker-controlled Blob content and MIME type are stored through the generated REST API, returned to privileged users, and opened as a same-origin Blob document from the generated Angular/React/Vue UI. Exploitability should be confirmed against the generated app’s CSP and target browsers. ## Details The root cause is a trust-boundary failure across generated server and client code. The generated entity REST resource accepts request bodies for entity creation and update. Unless an entity-specific authority is configured, the template omits method-level `@PreAuthorize`, leaving the endpoint available to any authenticated user under the global `/api/**` security rule. The generated DTO/domain/mapper flow stores the companion `<field>ContentType` property as a plain `String` and persists it with the entity Blob data. The relevant templates include `generators/spring-boot/templates/src/main/java/_package_/_entityPackage_/service/dto/_dtoClass_.java.ejs:96-122` and `generators/java/generators/domain/templates/src/main/java/_package_/_entityPackage_/domain/_persistClass_.java.jhi.ejs:124-140`. The generated code does not restrict MIME types, reject active document formats, or validate that the declared content type matches the uploaded bytes. The dangerous sink is `openFile` in `generators/client/generators/common/templates/src/main/webapp/app/shared/jhipster/data-utils.ts.ejs:49-64`. It uses the returned `contentType` as the Blob type, creates an object URL, and calls `globalThis.open(fileURL)`. Generated Angular, React, and Vue entity pages pass server-returned Blob data and ContentType into this helper, allowing active HTML or SVG content to be opened as a document under the application origin depending on CSP and browser behavior. Core vulnerable code path: ```typescript // generators/client/generators/common/templates/src/main/webapp/app/shared/jhipster/data-utils.ts.ejs:49-64 export const openFile = (data: string, contentType: string | null | undefined): void => { contentType ??= ''; const byteCharacters = atob(data); const byteNumbers = new Array(byteCharacters.length); for (let i = 0; i < byteCharacters.length; i++) { byteNumbers[i] = byteCharacters.codePointAt(i); } const byteArray = new Uint8Array(byteNumbers); const blob = new Blob([byteArray], { type: contentType, }); const fileURL = globalThis.URL.createObjectURL(blob); const win = globalThis.open(fileURL); if (win) { win.onload = () => URL.revokeObjectURL(fileURL); ``` The shared client sink trusts the incoming contentType, builds a Blob with that type, and opens it through a generated object URL. Active MIME types can therefore become executable documents when opened, depending on CSP and browser behavior. ## POC Preconditions: the target application is generated by generator-jhipster v9.2.0; it includes an entity with a Blob, AnyBlob, or ImageBlob field; the entity has no entityAuthority restriction or the attacker has write permission; the attacker has a normal account and a higher-privileged victim can view the entity detail or list page. Reproduction: (1) Generate an application with a Blob-bearing entity, for example a Document entity with a payload AnyBlob field. (2) Authenticate as a normal user and send POST /api/documents with Authorization: Bearer <attacker-token> and Content-Type: application/json. The request body contains a Base64-encoded active document in the payload field and a payloadContentType value such as text/html. (3) Confirm that the API returns HTTP 201 and that GET /api/documents/{id} returns the same payload and payloadContentType. (4) Have a privileged user open the generated entity detail or list page and click the Blob field’s Open link. Expected result: the browser opens a blob:<target-origin>/... document; where CSP and browser behavior permit script execution, the document can read Web Storage tokens or call same-origin APIs such as /api/account and privileged /api/admin/** endpoints as the victim. ## Impact A normal authenticated user can persist active content that a privileged user may open from the generated UI. Successful exploitation can result in stored cross-site scripting, JWT/localStorage/sessionStorage theft, sensitive API data disclosure, and privileged actions under the victim’s session. Default CSP may reduce exploitability, so deployments with relaxed CSP or browser behavior that allows script execution in opened Blob documents are at highest risk.

CVSS v3.1

Score 7.6high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Affected software

jhipster

generator-jhipster

Affected versions
<9.4.0

jhipster

react-jhipster

Affected versions
<1.1.0
generator-jhipster
pkg:npm/generator-jhipster
Affected versions
<9.4.0
react-jhipster
pkg:npm/react-jhipster
Affected versions
<1.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 17:48:33 UTC

Technical Analysis

JHipster's generator-jhipster versions before 9.4.0 and react-jhipster before 1.1.0 have an XSS vulnerability due to improper neutralization of input when generating web pages. Specifically, attacker-controlled Blob data and associated ContentType values can be stored and later returned through REST endpoints. The generated openFile helper uses the ContentType as the MIME type for a browser Blob and opens an object URL, which may execute malicious HTML or SVG content under the application origin if a privileged user opens it. This vulnerability depends on the content security policy of the generated application and the target browser's Blob handling. The vulnerability is addressed in versions 9.4.0 and 1.1.0 respectively.

Potential Impact

An authenticated user with write access to a Blob-bearing entity can store malicious active content that may execute in the context of the application when accessed by a privileged user. This can lead to high confidentiality impact due to potential unauthorized actions or data exposure. The integrity impact is limited to low, and availability is not affected. Exploitability depends on the application's content security policy and browser behavior.

Mitigation Recommendations

This vulnerability is fixed in generator-jhipster version 9.4.0 and react-jhipster version 1.1.0. Users should upgrade to these versions or later to remediate the issue. No additional mitigation actions are specified beyond applying the official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T15:53:23.587Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7d49a2cdf04f6562c68ab

Added to database: 10/08/2026, 17:36:26 UTC

Last enriched: 10/08/2026, 17:48:33 UTC

Last updated: 10/08/2026, 21:48:49 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses